Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 202778

Summary: sys-kernel/*-sources <=2.6.23.X "mmap_min_addr" Local Security Bypass Vulnerability (CVE-2007-6434)
Product: Gentoo Security Reporter: Lars Hartmann <lars>
Component: KernelAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: normal CC: kernel
Priority: High    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: http://www.frsirt.com/english/advisories/2007/4200
Whiteboard: [linux < 2.6.23.15][gp < 2.6.23-8]
Package list:
Runtime testing required: ---

Description Lars Hartmann 2007-12-19 13:33:44 UTC
Linux kernel 2.6.23 allows local users to create low pages in virtual userspace memory and bypass mmap_min_addr protection via a crafted executable file that calls the do_brk function.

Solution:
apply patch: http://groups.google.com/group/linux.kernel/browse_thread/thread/13bde11d06876040

Reproducible: Always
Comment 1 unnamedrambler 2008-03-21 20:09:09 UTC
[linux < 2.6.23.15] a0209f336a1dff0363b558a972eb71eef74e0084
also in 2.6.24 as ecaf18c15aac8bb9bed7b7aa0e382fe252e275d5 and 5a211a5deabcafdc764817d5b4510c767d317ddc ?


[gp < 2.6.23-8]